An internal product security audit discovered a session handling vulnerability in the web interface of ThinkAgile CP-SB (Storage Block) BMC in firmware versions prior to 1908.M. This vulnerability allows session IDs to be reused, which could provide unauthorized access to the BMC under certain circumstances. This vulnerability does not affect ThinkSystem XCC, System x IMM2, or other BMCs.
References
Link Resource
https://support.lenovo.com/solutions/LEN-26957 Vendor Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: lenovo

Published: 2019-09-24T00:00:00

Updated: 2019-09-26T15:22:15

Reserved: 2019-01-11T00:00:00


Link: CVE-2019-6161

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2019-09-26T16:15:11.970

Modified: 2019-10-01T13:38:44.840


Link: CVE-2019-6161

JSON object: View

cve-icon Redhat Information

No data.

CWE